Quick googling found out that at least one guy did come very close to realizing that 4-way handshake should have hard replay protection: http://slideplayer.com/slide/5762070/
On page 30 of the presentation: "Authenticator may (or may not) re-use ANonce"
On page 30 of the presentation: "Authenticator may (or may not) re-use ANonce"